Nepali Date Converter Security & Risk Analysis

wordpress.org/plugins/nepali-date-converter

Convert English dates to Nepali and vice versa, including WordPress post dates. Includes widgets, shortcodes, and custom functions.

900 active installs v3.0.5 PHP 7.2+ WP 4.9+ Updated May 18, 2025
english-to-nepali-date-converternepali-date-converternepali-post-datenepali-to-english-date-convertertoday-nepali-date
99
A · Safe
CVEs total1
Unpatched0
Last CVEApr 11, 2025
Safety Verdict

Is Nepali Date Converter Safe to Use in 2026?

Generally Safe

Score 99/100

Nepali Date Converter has a strong security track record. Known vulnerabilities have been patched promptly. It's a solid choice for most WordPress installations.

1 known CVELast CVE: Apr 11, 2025Updated 1yr ago
Risk Assessment

The 'nepali-date-converter' v3.0.5 plugin exhibits a generally strong security posture, particularly in its handling of SQL queries and output escaping, which are largely implemented correctly. The absence of dangerous functions, file operations, and external HTTP requests is also a positive indicator. Furthermore, the plugin utilizes nonce checks for its AJAX handlers, a crucial security measure. However, the analysis reveals a concerning lack of capability checks on its entry points. While the static analysis did not find immediate exploitable vulnerabilities, the absence of capability checks means that any user, regardless of their WordPress role, could potentially trigger the plugin's AJAX handlers, which could lead to unintended actions or information disclosure if not properly secured within the handler's logic itself.

The plugin's vulnerability history shows a single known CVE in the past, which is now patched. This suggests a willingness to address security issues, but the presence of even one past vulnerability warrants continued vigilance. The common vulnerability type being Cross-site Scripting is a reminder that input validation and output sanitization are critical, and while the current output escaping is high, the past history means this area should be continuously monitored. Overall, the plugin has good foundational security practices, but the missing capability checks on entry points represent a significant area for improvement to further harden its security.

Key Concerns

  • Missing capability checks on entry points
  • Past CVE: Improper Neutralization of Input During Web Page Generation ('Cross-si
Vulnerabilities
1 published

Nepali Date Converter Security Vulnerabilities

CVEs by Year

1 CVE in 2025
2025
Patched Has unpatched

Severity Breakdown

Medium
1

1 total CVE

CVE-2025-26950medium · 6.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Nepali Date Converter <= 2.0.8 - Authenticated (Contributor+) Stored Cross-Site Scripting

Apr 11, 2025 Patched in 3.0.0 (6d)
Version History

Nepali Date Converter Release Timeline

v3.0.5Current
v3.0.4
v3.0.3
v3.0.2
v3.0.1
v3.0.0
v2.0.81 CVE
v2.0.71 CVE
v2.0.61 CVE
v2.0.51 CVE
v2.0.41 CVE
v2.0.31 CVE
v2.0.21 CVE
v2.0.11 CVE
v2.0.01 CVE
v1.0.11 CVE
v1.01 CVE
Code Analysis
Analyzed Mar 16, 2026

Nepali Date Converter Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
6
155 escaped
Nonce Checks
3
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

96% escaped161 total outputs
Attack Surface

Nepali Date Converter Attack Surface

Entry Points5
Unprotected0

AJAX Handlers 3

authwp_ajax_ndc_date_formatinc\class\ndc-post-date.php:86
authwp_ajax_nepali_date_converter_ajaxinc\hooks\wp-ajax.php:12
noprivwp_ajax_nepali_date_converter_ajaxinc\hooks\wp-ajax.php:13

Shortcodes 2

[nepali-date-converter] inc\shortcode\shortcode-nepali-date-converter.php:13
[ndc-today-date] inc\shortcode\shortcode-today-date.php:13
WordPress Hooks 10
actionadmin_initinc\class\ndc-post-date.php:84
actionadmin_headinc\class\ndc-post-date.php:85
actioninitinc\class\ndc-post-date.php:87
filterget_the_timeinc\class\ndc-post-date.php:617
actionwp_enqueue_scriptsinc\hooks\enqueue-scripts.php:27
actionwp_enqueue_scriptsinc\widgets\widget-nepali-date-converter.php:35
actionwp_footerinc\widgets\widget-nepali-date-converter.php:36
actionwidgets_initinc\widgets\widget-nepali-date-converter.php:220
actionwidgets_initinc\widgets\widget-today-date.php:198
actionplugins_loadednepali-date-converter.php:46
Maintenance & Trust

Nepali Date Converter Maintenance & Trust

Maintenance Signals

WordPress version tested6.8.5
Last updatedMay 18, 2025
PHP min version7.2
Downloads14K

Community Trust

Rating100/100
Number of ratings4
Active installs900
Developer Profile

Nepali Date Converter Developer Profile

AddonsPress

5 plugins · 92K total installs

76
trust score
Avg Security Score
95/100
Avg Patch Time
221 days
View full developer profile
Detection Fingerprints

How We Detect Nepali Date Converter

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/nepali-date-converter/assets/css/script.css/wp-content/plugins/nepali-date-converter/assets/js/widget.js
Script Paths
/wp-content/plugins/nepali-date-converter/assets/js/widget.js
Version Parameters
nepali-date-converter/assets/css/script.css?ver=nepali-date-converter/assets/js/widget.js?ver=

HTML / DOM Fingerprints

CSS Classes
widget_nepali_date_converter
Data Attributes
data-nepali_date_langdata-nep_to_eng_button_textdata-eng_to_nep_button_textdata-disable_ndc_convert_nep_to_engdata-disable_ndc_convert_eng_to_nepdata-nepali_date_converter_result_format
JS Globals
ndc_widget_data
FAQ

Frequently Asked Questions about Nepali Date Converter